The Power of Immutable Data in Financial Services and Beyond – George Tziahanas, Archive360
Immutable data essentially refers to data within an environment that can’t be altered, overwritten or deleted. The information exists in a secure environment, either on-premises or in the cloud. It’s actually been a regulatory requirement in financial services data for nearly two decades, specifically to guard against inadvertent or intentional deletion. Now, enterprises can leverage this model as another level of protection for critical business information.
Transcript
This is Textron tv. Hey guys, thanks for the throw. We're here with George Zais, he's associate General counsel and VP of Compliance for Archive 360.
And we're gonna be talking about immutable data. You know, that's stuff that some people think is only associated with, uh, cryptocurrency, but it turns out that it has uses elsewhere. George, welcome to show.
Thanks very much. I think people are starting to come around to this idea, but maybe you should explain it. Immutable data means what?
I mean, it's should be data that doesn't change. And this doesn't sound like a brand new idea, but maybe we're starting to think about it more in the context of cybersecurity and data protection. What's going on?
That's right. So, um, it's definitely not new. What's interesting, and I'll walk through this a little bit, um, historically, we've actually dealt with, um, data in an immutable form, um, in financial services, really now for about two decades.
And immutability just means that it's an object that once written, uh, cannot be altered, cannot be deleted or overwritten. And so that way that, you know, that that object, that document, that file, that email is authentic because from the moment in time in which it's been put down onto immutable storage or into immutable system, it hasn't changed. Now we've been dealing with ransomware attacks for, I don't know, it feels like forever, but probably half a decade.
And all of that is about somebody trying to change the data, they encrypted and then we can't get at it. Or sometimes they just steal it. But that's a separate issue altogether.
But, um, what's taken us so long to kind of connect the dots between the need for immutable data and cybersecurity? Uh, probably a couple things. Um, one for a long time immutable, uh, really to enforce immutability, you had to have specialized, uh, storage platforms.
Those tended to be kind of expensive. They tended to be used, again, primarily for compliance purposes. We're not broadly deployed, we're not widely available in cloud environments.
And so it was, uh, both an availability and a cost, I think, uh, thing. And then in time, I think people started to realize, hey, maybe there's, uh, a use case beyond those regulatory reasons, but now in cybersecurity that we should be contemplating it. So is that capability being embedded?
How does it show up within my security platform or my backup and recovery platform or at the operating system? Where does one become immutable? A couple different ways that, uh, you're seeing this, right?
And so, um, Gartner describes this almost as a separate immutable. They talk about it like an immutability vault, really kind of in a backup or recovery environment, air gaped where you're sending certain types of data to an environment that's designed to again, place these objects, content, whatever it is, uh, in, in, in immutable, um, immutably set. And, and that can be at really at a hardware level, really at the storage level.
Um, and that's typically where it's done. Um, and you need generally also that carry that up through the application, uh, as well. So the one use case is more the backup and, um, set that stuff aside in case we need it for, uh, uh, if we did get attacked.
But if you look now, Microsoft even is providing, IM immutability within their environments, um, at in blob storage. And so you can actually set objects, immutably both at a, at a container or cabinet level, and now all the way down to a file level. And that immutability can be set to, um, enforce different retention requirements, but again, provides that, that protection around change, alter it, alteration or overriding.
Am I continuously updating that archive then or whatever that mechanism is, or do I kind of have some subset of my data that's immutable, but there might be a gap between what I'm processing in real time versus what's immutable? How, how real is real time? It, it depends again, on the use cases, right?
So some of the use cases are real time where you're taking in, especially for the regulated firms, again, you're taking in content pretty much in real time or near real time, and that's getting written down right away, and that's constantly updated. Um, for, for people who are doing this purely for a, um, a data protection, um, cyber protection use case, uh, I, you're starting to see people do this a little bit more like a backup recovery kind of thing. So you're, you're taking snapshots, you're doing that, you know, on a periodic basis, whatever those might be.
Maybe you do do some incrementals and, and critical systems and, and put those out into those air gap environments. Aren't we getting better at the recovery side of the equation? It seems to me when we first started out talking about data protection, it was all about making sure that we actually backed the thing up in the first place.
But now given these attacks, I think there's a lot more focus on how quickly can we recover. So are we, have we got that down to like seconds and minutes? Are we still talking about hours and days?
Uh, yeah, you know, to, so it's interesting, um, where you're doing the real time and you've got environments that are designed where the, the objects are immutable, the applications around them are designed to work with immutable objects. The recovery on those is really quick because they're, they're really designed to work with immutable objects as they exist, right? In, in that timeframe, when you're talking about recovery from a backup or some sort of redundant, um, air gap system.
Yeah. Then you're still talking usually some number of minutes or hours, um, to bring those systems back online, Right? You're also a lawyer, so I'm gonna ask you to put that hat on for a minute.
But, um, we see a lot of proposed legislation for holding people more accountable for their data and how they manage it. And if they lose it, maybe they'll get sued. Who knows?
Um, are we reaching a point where maybe the court systems are gonna expect that you don't lose data because it should be immutable? I mean, what's the awareness of what the value proposition is in the state of data management? You know, like everything else in time, um, uh, accepted practices or what practices people will consider reasonable protect data have changed, you know, 10 years ago, the level of sophistication that you had to have in your cyber practices is very different than you do today.
What's expected? Um, it's also what's expected to even just get cyber insurance, right? I mean, if you were, you had a cyber practice that looked like it did 10 years ago today, your chances of getting cyber insurance would be pretty, pretty low.
And so, you know, law, the laws themselves don't necessarily need to change, but what is accepted practice, reasonable accepted practice in the industries is usually how, um, that that evolves in, in case law, Right? Well, to that end, are we getting better at data management? Most of the organizations that I know would not get a good housekeeping seal of approval for the way they manage data.
Like everything. It, it's a, it runs a spectrum. I, I think it is getting better.
Um, I think there's a couple other, other things from a hygiene perspective people really need to be thinking about. Um, I've been writing about it and we've been talking quite a bit around data retirement, you know, getting data out of an operational system when it's no longer really necessary. You know, if you, you think about information, the value of it decays over time, but the risk actually goes up over time.
Uh, the systems where legacy data, uh, often lives are poorly maintained. They're, they're not patched as well. They don't have the latest security capabilities within them.
Um, and a lot of people often have access into these environments, and, and that's where mistakes are or intentional acts happen. And so the more you can do to get stuff out of operational systems, you don't need the better off you are. And that's, that's one big trend we, we see.
You cannot walk down the street these days without somebody leaping out to tell you about their great new AI thing. So do you think AI will get applied to help us figuring out what data might be, uh, worthy of removal? Maybe we could have a bring out your dead day to day.
I don't know. You know, what's your thought process? No question.
I mean, the, the volumes that we're talking about in the complexity of the environments, like technology has to get applied and, and AI and machine learning. We've been using them in, in e discovery use cases and compliance use cases for really for years now. But doing it at scale is a whole different thing.
Um, AI is now gonna create volumes of data that we haven't even thought of yet. And I haven't seen really good estimates yet. They're, they're big guesses, right?
Like just the amount of data we've created without robots being able to do it, you know, um, you know, in a snap that's gonna create tons of content. And so that we will have to apply a lot of AI and ML to these environments to determine what we keep and what we don't. There's also a big trend, um, internationally, um, to keep certain sets of information in country.
Uh, and that, um, also requires levels of data classification. These classes of data have to stay here. These classes of data can go there.
That also is where you need to apply some, a AI and ml, typically, Some of the privacy legislation says that I have the right to be forgotten. So if my data's immutable, how do I get rid of said data and comply with the privacy policy Comply policy? So immutability tends to be, uh, you, you, you usually will set immutability for a period of time, so you want to usually tie immutability to a time period.
And that's ty typically how the systems work as well. So if you, and then this is where you also really have to understand your workloads, right? So if you are working with a lot of content that's very active, a lot of privacy related, um, content in there, you know, maybe if it's not subject to some longer retention period, you set a retention period around it, it's protected for that some period of time.
But you know that when you get that order to go and destroy data, you can do so in whatever it is, you know, 60 days, 90 days, something like that. Hmm. So ultimately, do you think data has become like the last line of defense for cybersecurity?
Or maybe it is the only line of defense because everything else has shown itself to be fairly poor? It's certainly, you know, like everything else, uh, in cybersecurity, you gotta work through the layers, right? And data is definitely an important layer.
Um, uh, again, I think the broad availability or the, the broadening availability of immutability will definitely help. Uh, and it's something clients and customers should really be looking at for certain workloads. Um, and, uh, yeah, at the end of the day, it's the data that people want.
Um, obviously they want to get into your systems if they can and poke around and stay there, but ultimately it's, it's the data they hold ransom or it's the, uh, the data that they want to, um, take and look at and do something with. So what's your best advice to folks at this point? What's the things you see people doing that just make you shake your head and go, folks, I think we need to be better than this.
Yeah, a couple things, right? I think one, really understand the workloads that are gonna be critical and the sources of data that are critical to your operation, and make sure that you do have a plan for getting those, um, either immutable, um, stored immutably, or you've got air gapped backups that, that are immutably stored so you can recover quickly. Uh, and then there's the other thing, like I mentioned before, is start thinking about the data that you don't need in those operational systems anymore.
Um, you know, it's just, it's just creating more risk and you usually are not deriving that much value of it, uh, out of that, that information over time. All right, folks, well, you heard it here. Immutable data is kinda like the it equivalent of your permanent record.
You definitely wanna have one, just make sure it's updated and current and correct. But other than that, at least if you do that, your cybersecurity headache should be a lot less. George, thanks for being on the show.
That's a pleasure. Thanks. Thanks for having me here.
Alright, back to you guys in the.